Access authority management method and system of industrial internet

Through role responsibilities analysis and weighted voting processing, the problem of rigid decision-making and coordination difficulties in industrial Internet access rights management is solved, transparent and traceable permission management is achieved, and the security and efficiency of the system are improved.

CN120474843AInactive Publication Date: 2025-08-12SHENZHEN BAOJIANTOU INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510969395.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-08-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing industrial Internet access permission management methods have problems such as rigid decision-making, difficulty in coordination and opaque process, resulting in unreasonable permission allocation and affecting production efficiency and security.

Method used

By obtaining role responsibility description data, feature extraction and clustering analysis are performed, decision-making influence coefficient is calculated based on historical decision accuracy, weighted voting processing is performed, and opinions divergence is quantified, transparent authority expansion decisions are generated, and decision-making audit paths are recorded.

Benefits of technology

It has achieved multi-party collaboration, risk quantification and transparent process authority management, improved the scientificity and security of authority decisions, and enhanced the traceability and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474843A_ABST
    Figure CN120474843A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial internet access authority management method and system, and aims to solve the technical problems of subjective authority management decision, difficult collaboration and opaque process, and the method comprises the steps: obtaining and carrying out the automatic classification of multiple roles based on responsibility description; calculating a dynamic decision influence coefficient of each role through a weighting model in combination with role classification and historical decision accuracy; weighted voting is carried out on opinions of all parties according to the coefficient, and the opinion divergence degree is quantified by adopting information entropy so as to evaluate the decision risk; and generating and automatically executing an authority decision according to the voting result and the risk assessment. When a high decision risk is identified, the user intention is intelligently analyzed, and an alternative scheme with a lower risk is recommended. According to the invention, the scientificity and rationality of authority decision can be obviously improved, efficient and transparent multi-party cooperation is realized, the initiative and intelligence of risk prevention and control are enhanced, and a safer and more reliable access control guarantee is provided for an industrial internet system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial Internet technology, and in particular to a method and system for managing access rights of the industrial Internet. Background Art

[0002] The Industrial Internet, a product of the deep integration of next-generation information technology and the industrial economy, has significantly improved manufacturing efficiency and resource collaboration by connecting devices, data, and people. In this context, access control is a core component of ensuring the secure and stable operation of Industrial Internet systems. It directly determines which personnel or systems can access which key equipment, production data, or control instructions. However, existing access management methods have exposed numerous flaws when dealing with complex industrial environments, primarily in the following areas: First, the decision-making mechanism is rigid and subjective. Traditional permission management often relies on manual approval by a single administrator (such as an IT administrator or security director), or judgments based on a pre-set, fixed set of rules. This approach is overly rigid in the face of complex and ever-changing industrial production scenarios. Limited by their knowledge and responsibilities, a single decision-maker struggles to fully assess the impact of a permission expansion request on production, security, operations, and other aspects. The decision-making process is highly subjective, which can easily lead to irrational permission allocation—either overly conservative, impacting production efficiency, or overly permissive, creating security risks.

[0003] Secondly, the lack of an effective multi-party collaboration mechanism leads to a chaotic decision-making process. A request for permission expansion, especially one involving core production systems, typically involves multiple stakeholders, such as project managers, equipment engineers, production line foremen, and safety auditors. These stakeholders each have different perspectives on the request from different perspectives, such as business, technology, and security. These opinions are often fragmented and potentially conflicting. Existing technologies generally lack a scientific and impartial mechanism to effectively integrate these opinions. The decision-making process often degenerates into ad hoc email exchanges or verbal negotiations, lacking unified rules of procedure and quantitative evaluation criteria. How can the opinions of different roles be weighted? How can arbitration be conducted when serious disagreements arise? The lack of standardized solutions to these key issues leads to a disorderly, chaotic, and inefficient decision-making process. The final decision is often the product of compromise rather than the optimal solution.

[0004] Third, the decision-making process is opaque and difficult to trace. Due to the chaotic and unstructured nature of the decision-making process, traditional authority-based decision-making is often poorly documented and lacks transparency. Crucial information such as the rationale for the decision, the specific opinions of the various parties, the focus of disagreements, and the final basis for the ruling are often scattered across emails, chat logs, or even communicated verbally, failing to maintain a systematic record. When improper authority allocation leads to a production accident or safety incident, tracing the complete decision-making chain is difficult, making post-event auditing and assigning responsibility extremely challenging. This "black box" decision-making process not only increases decision-making risk but also undermines the overall credibility and reliability of the system.

[0005] In summary, existing technologies in the field of Industrial Internet rights management generally suffer from three core drawbacks: subjective decision-making mechanisms, chaotic collaborative processes, and opaque decision-making results. Therefore, this field urgently needs a new technical solution that not only addresses the limitations of a single decision-maker but also establishes a set of clear and quantified rules for collaborative decision-making among multiple parties. This solution also provides structured records of the data generated throughout the decision-making process, forming a traceable decision-making audit path. This approach systematically addresses the problems of one-sided decision-making, chaotic processes, and lack of transparency found in traditional solutions.

[0006] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present invention, and therefore may include information that does not constitute prior art known to ordinary technicians in this field. Summary of the Invention

[0007] In view of this, the present invention provides an access rights management method and system for the industrial Internet to solve the problems of decision-making rigidity, coordination difficulties and process opacity in the existing industrial Internet access rights management methods, and realize multi-party collaboration, risk quantification and process transparency of access rights management, thereby improving the security and reliability of the industrial Internet system.

[0008] An embodiment of the present invention provides an access rights management method for the industrial Internet, including: Obtain a dataset of responsibilities descriptions for roles related to permission expansion requests, perform feature extraction and cluster analysis on the responsibilities description data, and obtain classification labels for each role. Based on each role's classification label and combined with the role's historical decision accuracy data extracted from historical authority decision records, the decision influence coefficient of each role is calculated through a preset weighted model; Obtain the opinion data entered by the role regarding the current permission expansion request, and perform weighted voting on the opinion data based on each role's decision-making influence coefficient to obtain preliminary voting results; Based on the distribution ratio of support and opposition in the preliminary voting results, the information entropy calculation method is used to quantify the degree of disagreement to identify the risk of decision conflict; Generate and execute the final authority expansion decision based on the preliminary voting results and decision conflict risks.

[0009] In some optional embodiments, the step of performing feature extraction and cluster analysis on the job description data includes: Use the term frequency-inverse document frequency algorithm to convert the job description data into text feature vectors; and The K-means algorithm is used to cluster the text feature vectors to assign a classification label to each role.

[0010] In some optional embodiments, the preset weighted model also combines the decision participation frequency data of each role obtained from historical authority decision records, and performs weighted calculations together with the historical decision accuracy data and the responsibility weights corresponding to the classification labels.

[0011] In some optional embodiments, the step of performing weighted voting further includes: Before weighting, monitor the deviation between each role's current opinion data and its historical decision accuracy data; When the deviation value exceeds the preset threshold, the decision-making influence coefficient of the role in this weighted voting process is dynamically lowered.

[0012] In some optional embodiments, after obtaining the opinion data and before performing the weighted voting process, the following steps are further included: Use the natural language processing model to analyze the sentiment tendency of opinion data and determine a sentiment weight value for each opinion data; The steps of weighted voting processing specifically include multiplying the decision-making influence coefficient of each role by the emotional weight value corresponding to the opinion data submitted by the role to obtain an effective decision-making influence; and using the effective decision-making influence to weight the opinion data.

[0013] In some optional embodiments, after generating the final rights expansion decision, the following steps are further included: All data and processing processes including classification labels, decision influence coefficients, opinion data, preliminary voting results, and decision conflict risks are recorded in a structured manner in the visual log module to form a traceable decision audit path.

[0014] In some optional embodiments, before generating the final rights expansion decision, the following steps are further included: Calculate the fairness assurance index corresponding to the preliminary voting results; If the fairness assurance index is lower than the preset fairness threshold, the secondary opinion collection process will be triggered, and the preliminary voting results will be regenerated based on the opinion data obtained from the secondary collection.

[0015] In some optional embodiments, when a decision conflict risk is identified or a fairness assurance index is determined to be lower than a preset fairness threshold, the process further includes: Parse the work intent text contained in the permission expansion request to determine the core operation and target object of the request; Based on the core operation and the target object, automatically generate at least one alternative whose scope of authority is smaller than the original request in terms of time, space, or operation type; Submit the alternative proposal for a new round of comment and weighted voting.

[0016] An embodiment of the present invention further provides an access rights management system for the Industrial Internet, including: The role information processing module is used to obtain the role description dataset related to the permission expansion request and perform feature extraction and cluster analysis on the role description data to determine the classification label of each role; The influence assessment module is used to determine the decision-making influence coefficient of each role based on the classification label of each role and the historical decision accuracy data of the role extracted from the historical authority decision records. The decision integration module is used to obtain the opinion data input by the roles regarding the current permission expansion request and perform weighted voting on the opinion data based on the decision influence coefficient of each role to obtain the preliminary voting results; The risk analysis and execution module is used to quantify the degree of disagreement based on the distribution ratio of support and opposition in the preliminary voting results, using information entropy calculation to identify decision conflict risks, and generate and execute the final authority expansion decision based on the preliminary voting results and decision conflict risks.

[0017] In some optional embodiments, the decision integration module is also used to: monitor the deviation value between each role's current opinion data and its historical decision accuracy data when performing weighted voting processing, and dynamically lower the role's decision influence coefficient in this processing when the deviation value exceeds a preset threshold.

[0018] In some optional embodiments, the method further includes: The decision tracing module is used to record in a structured manner the data generated by the role information processing module, influence assessment module, decision integration module and risk analysis and execution module during the processing process, so as to form an auditable decision tracing path.

[0019] In some optional embodiments, the method further includes: The alternative solution generation engine is used to analyze the work intention of the permission expansion request when the risk analysis and execution module identifies the decision conflict risk, and automatically generate at least one alternative solution with a smaller permission scope than the original request for the decision integration module to carry out a new round of decision processing.

[0020] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the invention.

[0021] The method and system for managing access rights for the industrial Internet of the present invention have the following beneficial effects: The role information processing module automatically identifies role categories and dynamically calculates decision weights, making permission decisions more objective and fair, balancing business needs and security requirements. The decision integration module enables multi-party collaborative decision-making, improving the efficiency of processing complex permission requests. The risk analysis and execution module quantifies disagreements and introduces alternative solutions, proactively identifying decision risks and enhancing the intelligence of permission management. The decision tracing module records the entire decision-making process in detail, forming a clear audit path, providing data support for post-analysis and responsibility delineation, and enhancing the transparency and traceability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Other features, objects and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings.

[0023] Figure 1 This is a flow chart of a method for managing access rights for the Industrial Internet according to an embodiment of the present invention; Figure 2 It is a structural diagram of an access rights management system for the industrial Internet according to one embodiment of the present invention. DETAILED DESCRIPTION

[0024] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be embodied in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0025] In addition, the accompanying drawings are merely schematic illustrations of the present invention and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the blocks shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0026] The flowcharts shown in the accompanying drawings are merely exemplary and do not necessarily include all steps. For example, some steps may be decomposed, while some steps may be combined or partially combined. Therefore, the actual execution order may change according to actual circumstances.

[0027] The present invention relates to the field of access rights management, and utilizes role classification, influence assessment, opinion integration, and risk quantification to achieve more scientific and reasonable authority allocation decisions. Role classification draws on cluster analysis methods in natural language processing and machine learning. By extracting key information from role responsibilities descriptions, roles with similar responsibilities are grouped together, which helps to more accurately understand the expertise and focus of different roles in authority decision-making. Influence assessment integrates statistics and decision theory. By quantifying the accuracy of historical decisions of roles and the importance of responsibilities, different roles are given different decision weights, thereby avoiding the deviation caused by subjective judgment in traditional authority management. Opinion integration draws on voting theory, synthesizing opinions from all parties through weighted voting, and using information entropy to quantify the degree of disagreement, which can effectively identify potential decision-making risks. The rationality and security of the authority allocation scheme are improved. The root cause is that this method can integrate the professional knowledge of multiple parties and conduct quantitative assessments of potential risks, ultimately achieving a transparent, traceable and scientific authority management mechanism.

[0028] like Figure 1 As shown, an embodiment of the present invention provides an access rights management method for the industrial Internet, including: S100: Obtain a role description dataset related to the permission expansion request, perform feature extraction and cluster analysis on the role description data, and obtain a classification label for each role; In the Industrial Internet environment, permissions management isn't an isolated process; it's closely tied to the responsibilities of multiple stakeholders. This step aims to systematically identify and understand the responsibilities of these roles, providing a foundation for subsequent permissions decisions. Specifically, a role description dataset is obtained for the roles associated with the permissions expansion request. This dataset automatically identifies the responsibilities of key roles involved in the decision, such as equipment engineers, safety auditors, and production supervisors, based on the resources, systems, and security policies affected by the permissions change. The system can automatically identify roles using predefined role-resource association rules, access control lists (ACLs), or a graph-based knowledge graph. Responsibility description data refers to textual information describing the specific work content and scope of a role, such as job descriptions and departmental rules and regulations. This data reflects the role's role and responsibilities within the Industrial Internet system. Feature extraction involves extracting key information from this textual information, such as keywords, phrases, and themes, that represents the role's responsibilities. Natural language processing (NLP) techniques, such as term frequency-inverse document frequency (TF-IDF) and word embedding, can be used to convert textual information into computer-processable numerical vectors. Cluster analysis involves categorizing roles into different categories based on the similarities of their responsibilities, such as "security management," "equipment maintenance," and "production operations." Clustering algorithms, such as K-means and hierarchical clustering, can be used to automatically classify roles. The classification labels are then used in subsequent steps as a basis for assessing the influence of role decisions. This step enables the system to understand the potential value and risks of each role in permissions management, providing a basis for subsequent weighted voting. For example, role responsibility information can be obtained from a database, LDAP directory, or API interface. This responsibility information is a textual description of each role's work content, scope of authority, and responsibilities. Optionally, topic models (such as LDA) or deep learning models (such as BERT) can be used for more advanced feature extraction to obtain a more accurate responsibility vector representation. Alternatively, algorithms such as DBSCAN or spectral clustering can be used to better adapt to role responsibility data of varying shapes and densities.

[0029] This embodiment can accurately identify roles related to permission expansion requests and classify them according to their scope of responsibilities through feature extraction and cluster analysis of role responsibility description data, providing a basis for subsequent decision-making influence assessment, thereby avoiding the problems of traditional permission management relying on the subjective judgment of a single administrator and the lack of an effective multi-party collaboration mechanism in the decision-making process.

[0030] S200: Based on the classification label of each role and in combination with the historical decision accuracy data of the role extracted from the historical authority decision records, the decision influence coefficient of each role is calculated through a preset weighting model; The role classification label reflects the role's responsibilities, while historical decision accuracy data reflects the quality of the role's past decisions. Combining these two data points and calculating them through a weighted model can more accurately assess the role's influence in current permission decisions.

[0031] Historical decision accuracy data is extracted from historical permission decision records and is used to assess the quality of a role's past decisions. This data can be measured by counting the percentage of permission requests approved or denied by the role that were later proven to be correct, for example, without causing security incidents or achieving the expected benefits.

[0032] The preset weighted model integrates role classification labels and historical decision accuracy data. This weighted model can use linear weighting, nonlinear weighting, or a machine learning-based model. For example, different weight coefficients can be set for different role categories, and the weights can be dynamically adjusted based on historical decision accuracy data.

[0033] This embodiment can scientifically quantify the decision-making influence of each role by combining role classification labels and historical decision accuracy data, thereby avoiding the shortcomings of simple collaborative methods such as one person one vote or verbal negotiation in traditional authority management, and also avoiding the neglect of the professionalism and authority of different roles. In addition, the weighted model can be dynamically adjusted according to the historical decision-making performance of the role, making the decision-making process more intelligent and adaptive, thereby improving the scientificity and rationality of the decision. For example, for roles classified as security audit, a higher responsibility weight can be preset, representing that security compliance is crucial in authority decision-making. Historical decision accuracy data can be obtained by analyzing historical logs and counting the proportion of authority changes in which the role participated that ultimately did not lead to security incidents or compliance issues. In addition, the frequency of decision-making participation can be added as a consideration to encourage the active participation of relevant personnel. The weighted model can use a linear regression model or a neural network model to more flexibly fit the relationship between different factors. In addition, a time decay factor can also be introduced to reduce the impact of older historical decision data.

[0034] This step allows the system to comprehensively consider the importance of a role's responsibilities and historical decision-making performance, thereby more accurately assessing its influence on the current decision. Weighting models can be linear or nonlinear to adapt to different application scenarios. Weighted models effectively integrate multiple opinions, overcoming the rigid and subjective decision-making mechanisms of traditional rights management methods.

[0035] S300: Obtain the opinion data input by the roles regarding the current permission expansion request, and perform weighted voting on the opinion data based on the decision-making influence coefficient of each role to obtain a preliminary voting result: Opinion data represents the opinions and reasons provided by roles regarding permission expansion requests and serves as a crucial basis for decision-making. Weighted voting integrates the opinions of different roles and weights them based on their influence, ultimately forming a preliminary decision.

[0036] Opinion data refers to a role's view on a request to expand permissions. It can include options such as "agree," "disagree," and "abstain," as well as reasons and evidence supporting their views. The format of opinion data can be structured, for example, by selecting preset options and filling out a form, or unstructured, for example, free text. The system can provide a user-friendly interface for roles to easily enter opinion data. Weighted voting processing involves weighting opinion data based on the role's decision-making influence coefficient to determine the overall voting result. For example, a positive weight can be assigned to an agreeing opinion, and a negative weight can be assigned to an opposing opinion, with the absolute value of the weight equal to the role's decision-making influence coefficient. The weighted opinions of all roles are then summed to obtain a total score. If the total score is greater than zero, the preliminary voting result indicates an agreement; if the total score is less than zero, it indicates an opposition.

[0037] By acquiring role opinion data and performing weighted voting, this embodiment fully considers the views of various stakeholders and conducts a comprehensive assessment based on their expertise and historical performance, thereby avoiding the lack of effective multi-party collaboration mechanisms in traditional rights management and improving the democracy and rationality of decision-making. Opinion data can be acquired through structured forms or natural language input, facilitating the expression of information by different roles. Optionally, natural language processing can be performed on the opinion data to extract keywords and sentiment, thereby providing a more comprehensive understanding of the role's perspective.

[0038] S400. Based on the distribution ratio of support and opposition opinions in the preliminary voting results, the information entropy calculation method is used to quantify the degree of disagreement to identify the risk of decision conflict.

[0039] This step aims to quantify the uncertainty and potential risks in the decision-making process and prevent adverse consequences caused by excessive disagreement. The opinion distribution ratio reflects the relative strength of support and opposition, while information entropy measures the uniformity of the opinion distribution, that is, the degree of disagreement.

[0040] The opinion distribution ratio refers to the proportion of supporting and opposing opinions in the preliminary voting results. For example, if 70% of roles support expanding permissions and 30% oppose, the proportion of supporting opinions is 0.7 and the proportion of opposing opinions is 0.3. Information entropy is a measure of information uncertainty. In this invention, information entropy is used to measure the degree of disagreement. The greater the information entropy, the more dispersed the opinions and the higher the disagreement; the smaller the information entropy, the more concentrated the opinions and the lower the disagreement. Information entropy can be calculated using the Shannon entropy formula.

[0041] This embodiment quantifies the degree of disagreement through information entropy, enabling an objective assessment of the risk of decision-making conflicts. This avoids the opaque and difficult-to-trace decision-making process in traditional rights management and enhances the ability to control risk in decision-making. The opinion distribution ratio can be calculated by summing the weights of support and opposition in the weighted voting results. Alternatively, other risk assessment methods, such as expert scoring and risk matrices, can be used to comprehensively assess decision-making risks.

[0042] S500: Generate and execute the final authority expansion decision based on the preliminary voting results and the decision conflict risk.

[0043] The purpose is to comprehensively consider the opinions of all parties and the results of risk assessment, make a final decision, and put it into implementation.

[0044] The final permission expansion decision is the final outcome of the permission expansion request, which can be "approved," "rejected," or "requires further review." This decision takes into account both the preliminary voting results and the risk of conflicting decisions. For example, if the preliminary voting results favor approval and the risk of conflicting decisions is low, the permission expansion request can be approved directly. If the preliminary voting results favor rejection or the risk of conflicting decisions is high, the permission expansion request can be rejected or a more advanced decision process can be triggered.

[0045] By comprehensively considering the opinions of all parties and risk assessment results, this embodiment can generate more scientific, reasonable, and secure permission expansion decisions, thereby improving the overall intelligent level of permission management. The final decision can be executed through the API interface or automated scripts, realizing automatic configuration and update of permissions. Optionally, a manual review process can be introduced to manually intervene in high-risk permission changes.

[0046] The method provided in the embodiment of the present invention can realize multi-party collaboration, dynamic weighting, risk quantification and process transparency of industrial Internet access rights management through automated role identification, weighted voting, risk assessment and decision execution steps, improve the scientificity and rationality of decision-making, realize efficient multi-party collaborative decision-making, enhance the transparency and traceability of the system, improve the initiative and intelligence of risk prevention and control, and ultimately ensure the safe and stable operation of the industrial Internet.

[0047] In some embodiments, a term frequency-inverse document frequency algorithm is used to convert the job description data into a text feature vector; The K-means algorithm is used to cluster the text feature vectors to assign a classification label to each role.

[0048] This embodiment aims to convert unstructured role responsibilities description text into numerical data that can be processed and analyzed by computers, thereby realizing automatic classification of roles. Specifically, the term frequency-inverse document frequency (TF-IDF) algorithm is used to extract keywords from each role responsibilities description and quantify the importance of these keywords. The TF-IDF algorithm comprehensively evaluates the importance of each word by counting the frequency (TF) of the word appearing in a single role responsibilities description and the inverse frequency (IDF) of the word appearing in all role responsibilities descriptions. The higher the TF value, the more important the word is in the role responsibilities description; the higher the IDF value, the more discriminative the word is in all role responsibilities descriptions. Through the TF-IDF algorithm, the responsibilities description of each role is converted into a high-dimensional text feature vector that can reflect the responsibilities characteristics of the role. As an alternative implementation, other text feature extraction algorithms, such as deep learning models such as Word2Vec and BERT, can be used to obtain more accurate semantic information.

[0049] Furthermore, the K-means algorithm is used to cluster these text feature vectors to divide the roles into different categories. The K-means algorithm is an unsupervised learning algorithm that iteratively divides data points into K clusters so that the distance between each data point and the center point of the cluster to which it belongs is minimized. In the present invention, each text feature vector represents a role, and K clusters represent K role categories. Through the K-means algorithm, the system can automatically classify roles with similar job descriptions into the same category, thereby assigning a classification label to each role. As an alternative embodiment, other clustering algorithms, such as hierarchical clustering, DBSCAN, etc., can also be used. In addition, the selection of the K value can be adjusted according to the actual application scenario. For example, the elbow rule or silhouette coefficient method can be used to determine the optimal K value.

[0050] Through this feature extraction and cluster analysis, we can effectively transform unstructured role descriptions into structured role classification labels, providing a basis for subsequent influence coefficient calculation and permission decisions. This method can improve the accuracy and efficiency of role classification, reduce the cost of manual intervention, and thus enhance the automation of the entire access rights management method.

[0051] In some embodiments, a preset weighted model is used to comprehensively assess each role's influence in permission decisions. This model not only considers the role's historical decision accuracy and responsibility weight, but also incorporates decision-making participation frequency data, aiming to more comprehensively reflect the role's value and contribution to permission management. This weighted model enables a more scientific quantification of each role's decision-making influence coefficient, making the permission decision-making process more fair and reasonable. Specifically, the decision-making participation frequency data (Frequency Score, F) reflects the role's active participation in permission decisions within a certain timeframe. For example, the number of times a role participated in permission approvals, raised objections, or provided suggestions in the past month or quarter can be counted. A higher participation frequency indicates a greater level of concern for permission management, and their opinions should be given more weight. The introduction of this parameter aims to encourage relevant personnel to participate more actively in permission management on the Industrial Internet, thereby improving overall security and effectiveness.

[0052] In practice, the decision-making participation frequency F can be calculated as follows: Simple counting method: directly count the number of times a role participates in permission decision-making within a specific time period.

[0053] Weighted counting: Considering that different types of decisions may have different importance, different types of participation behaviors can be assigned different weights. For example, rejecting a high-risk permission request can be weighted higher than simply approving a low-risk request.

[0054] Normalization: To eliminate the impact of differences in participation frequency due to different role responsibilities, the original count can be normalized. For example, the raw count can be divided by the total number of decisions made by the department to which the role belongs to obtain the relative participation frequency.

[0055] At the same time, the responsibility weight R can be set based on the specific responsibilities of the role. For example, the responsibility weight of a "Security and Compliance" role can be set to 0.8-1.0 to reflect their security expertise; the responsibility weight of a "Technical Implementation" role can be set to 0.6-0.8 to reflect their technical expertise; and the responsibility weight of a "Business Management" role can be set to 0.4-0.6 to reflect their consideration of business impact. The weight values can be adjusted according to actual business needs.

[0056] The historical decision accuracy data H can be calculated by counting the proportion of requests approved / rejected by the role in the past that were ultimately proven correct, such as not causing an incident or bringing the expected benefits. For example, if 95 of a role's past 100 permission decisions were proven correct, their historical decision accuracy data is 0.95.

[0057] By comprehensively considering historical decision accuracy, responsibility weight, and decision-making participation frequency, the preset weighted model can more accurately assess the decision-making influence of each role, avoiding bias caused by a single factor and improving the scientific and rationality of decision-making. The formula can be shown as follows: DIC = α * H + β * R + γ * F Where: DIC is the final decision influence coefficient. H (History Accuracy Score) is the historical decision accuracy data of the role, ranging from [0, 1]. It is statistically derived from historical decision records and represents the proportion of requests approved / rejected by the role in the past that were ultimately proven to be correct, such as not causing an accident or bringing the expected benefits. R (RoleResponsibility Weight) is the responsibility weight corresponding to the role classification label and is a preset value. For example, the weight R for "Security Compliance" is s =0.9, weight of “Technical Implementation” R t =0.7, weight of “business management” R b = 0.6. This weight reflects the inherent importance of different areas of expertise in authority decisions. F (Frequency Score) is the decision participation frequency score, ranging from 0 to 1. It is calculated based on the number of times the role has participated in decision-making over a period of time and is used to encourage active participation. α, β, and γ are the weighting coefficients for each item, where α + β + γ = 1. For example, α = 0.5, β = 0.3, and γ = 0.2 could be set to prioritize historical accuracy.

[0058] By incorporating decision-making participation frequency into the weighted model, we can more comprehensively assess the value of roles in permission decisions, incentivize relevant personnel to actively participate in permission management, and thus improve overall security and effectiveness. This comprehensive assessment method helps balance the interests of all parties, avoid bias caused by a single factor, and make the decision-making process more fair and reasonable.

[0059] In some embodiments, the step of performing weighted voting further includes: Before weighting, monitor the deviation between each role's current opinion data and its historical decision accuracy data; When the deviation value exceeds the preset threshold, the decision-making influence coefficient of the role in this weighted voting process is dynamically lowered.

[0060] Current opinion data refers to the role's expressed position of approval, opposition, or neutrality regarding a specific permission expansion request, along with the specific reasons supporting that position. This data exists in a structured format, such as a JSON object or a record in a relational database. Historical decision accuracy data is a record of the role's past participation in permission decisions, including voting positions, decision time, related resources, and final decision outcomes. This data is used to assess the reliability and accuracy of the role's past decisions.

[0061] During the implementation process, a baseline of each role's historical behavior patterns is first established. For example, by counting the role's approval rate, disapproval rate, and decision-making preferences for specific resource types over a period of time, such as three months or six months, a behavioral pattern profile is formed. Current opinion data is then compared with this behavioral pattern profile to calculate a deviation value. This deviation value can be calculated in a variety of ways, such as by calculating the difference between the current voting position and the historical approval rate, or by calculating the semantic similarity between the current opinion reason and the historical opinion reason. If the deviation value exceeds a preset threshold (which can be dynamically adjusted based on the role's historical data), the role's current behavior is considered abnormal. To prevent abnormal behavior from interfering with decision-making, the role's decision-making influence coefficient in this weighted voting process needs to be dynamically lowered. For example, the role's DIC can be multiplied by an attenuation factor, such as 0.5 or 0.7, to reduce its voting weight.

[0062] For example, security auditor D had a history of high decision accuracy and typically maintained a conservative stance. Over the past year, he had opposed similar permission requests 90% of the time. However, in this case, D, contrary to his usual practice, agreed, providing ambiguous reasons. The system detected this anomalous behavior and calculated that the deviation between his opinion data and his historical behavior patterns exceeded a set threshold. Therefore, the system temporarily lowered his DIC, thereby reducing the impact of his anomalous behavior on the final decision.

[0063] By monitoring and adjusting for abnormal fluctuations in role behavior, this technical solution can effectively reduce decision-making risks caused by factors such as human error, malicious behavior, or information bias, thereby improving the security and reliability of overall permission management. The technical effect is to enhance the security of access rights management for the Industrial Internet, preventing the problem of unreasonable permission allocation caused by human error and malicious behavior, thereby improving the security of information systems.

[0064] In some embodiments, after obtaining the opinion data and before performing weighted voting, the following steps are further included: Using a natural language processing model to perform sentiment analysis on the reason text contained in the opinion data, and determining a sentiment weight value for each opinion data; The steps for weighted voting processing are specifically as follows: Multiply the decision influence coefficient of each role by the sentiment weight value corresponding to the opinion data submitted by that role to obtain an effective decision influence; and use the effective decision influence to weight the opinion data.

[0065] This embodiment aims to more precisely evaluate the quality of opinions. It not only considers the stance of opinions (agree / disagree), but also takes into account the intensity of opinion expression and emotional color, thereby improving the accuracy and rationality of decision-making. In a specific implementation, the natural language processing model can be a pre-trained model based on deep learning, such as BERT (Bidirectional Encoder Representations from Transformers), which has been trained on a large amount of text data and can accurately identify the sentiment tendency in the text. The specific implementation steps are as follows: 1. Data preprocessing and sentiment feature extraction: First, clean the reason text in each piece of opinion data collected, including removing irrelevant HTML tags, special characters, and stop words (such as "of", "is", "in", etc.).

[0066] Then, input the cleaned reason text into a fine-tuned BERT sentiment analysis model. To improve the accuracy of the model in industrial field scenarios, the publicly available BERT model can be fine-tuned (Fine-tuning) in advance using industrial field corpus data (such as equipment maintenance reports, production meeting minutes, etc.). After receiving the text input, the model outputs a standardized sentiment score, and the range of this score is [-1, 1], where -1 represents the most negative sentiment, 1 represents the most positive sentiment, and 0 represents neutral sentiment.

[0067] For example, for the three opinion reason texts mentioned earlier: The reason text of Supervisor B: "The PLC has occasional communication interruptions recently. Engineers need to thoroughly check the parameter configuration, and write permission is necessary." After model analysis, the output sentiment score is Semo B = +0.55.

[0068] The reason text of Manager C: "Support technical troubleshooting, quickly restore equipment stability, and ensure the production plan." After model analysis, the output sentiment score is Semo C = +0.80.

[0069] The reason text of Auditor D: "Directly opening the PLC write permission has too high a risk, which may lead to misoperations and cause production accidents. According to security policy C-113, such operations need to be verified in the simulation environment first." After model analysis, the output sentiment score is Semo D= -0.75.

[0070] 2. Determination of sentiment weight value: Map the sentiment score output by the model to an emotional weight factor (EWF). The purpose of this step is to convert the intensity of the sentiment into a multiplicative factor used to adjust the influence. The mapping function can be a linear function, for example: EWF = 1 + Semo * k Where Semo is the sentiment score and k is a configurable sensitivity coefficient, for example, k=0.5, which is used to control the adjustment range of the weight based on the sentiment intensity.

[0071] According to this mapping function, the sentiment weight value of each character is calculated: EWF B = 1 + 0.55 * 0.5 = 1.275 EWF C = 1 + 0.80 * 0.5 = 1.400 EWF D = 1 + (-0.75) * 0.5 = 1 - 0.375 = 0.625 3. Weighted voting process combined with sentiment weight: When performing weighted voting, the system no longer directly uses the original decision influence coefficient (DIC), but first calculates an effective decision influence (EDI). The EDI is obtained by multiplying the original DIC with the corresponding sentiment weight value EWF: EDI i =DIC i * EWF i Where i represents a specific role. Assume that the original decision-making influence coefficients of each role have been calculated from the previous steps: DIC B = 0.845, DIC C = 0.800, DIC D = 0.900.

[0072] Calculate the effective decision-making influence of each role: Supervisor B's effective influence: EDI B = 0.845 * 1.275 ≈ 1.077 Manager C's effective influence: EDI C = 0.800 * 1.400 = 1.120 Auditor D's Effective Influence: EDI D = 0.900 * 0.625 = 0.5625 Finally, the system uses this newly calculated effective decision influence (EDI) to perform a final weighted processing on the opinion data. Define agreement as +1 and opposition as -1, and calculate the final weighted voting score: WeightedVoteScore = Σ (EDI i * Vote i ) Score = EDI B * (+1) + EDI C * (+1) + EDI D * (-1) = 1.077 + 1.120 - 0.5625 = 1.6345 By introducing sentiment weighting, this embodiment enables a more comprehensive assessment of the value of opinions. For example, Manager C's strongly supportive opinion significantly increases its influence (from 0.800 to 1.120). While Auditor D, while already highly weighted, has a strongly cautionary dissenting opinion, this sentiment weighting also quantifies it. This approach effectively identifies and quantifies the emotional intensity of opinions, ensuring that the final decision reflects not only "who is speaking" but also "how they are speaking," thereby enhancing the objectivity and fairness of the decision.

[0073] In some embodiments, after generating the final rights expansion decision, the process further includes: All data and processing processes including classification labels, decision influence coefficients, opinion data, preliminary voting results, and decision conflict risks are recorded in a structured manner in the visual log module to form a traceable decision audit path.

[0074] After the final permission expansion decision is made, the following also needs to be done: All data and processing processes including classification labels, decision influence coefficients, opinion data, preliminary voting results, and decision conflict risks are recorded in a structured manner in the visual log module to form a traceable decision audit path.

[0075] The classification label summarizes the types of responsibilities within a role, helping to quickly understand its area of expertise. The decision-making influence coefficient reflects the importance of the role in decision-making and serves as the basis for subsequent weighted voting. Opinion data directly reflects the views of all parties, including support and opposition positions and their reasons. The preliminary voting result is the intermediate result of the weighted voting, reflecting the overall decision-making tendency. The decision conflict risk quantifies the degree of disagreement and is used to identify potential decision-making risks. Recording this data in a structured manner can fully present the basis and process of authority decisions, ensuring traceability of the decision-making process.

[0076] By structured recording and visually displaying the permission decision-making process, the system's transparency and traceability are greatly enhanced. When a security incident or compliance issue occurs, administrators can quickly locate the relevant decision-making process, identify the decision-making basis, the involved personnel, and the risk assessment results. This provides strong support for problem analysis and responsibility delineation, thereby improving overall security management.

[0077] In some embodiments, before generating a final rights expansion decision, the process further includes: Calculate the fairness assurance index corresponding to the preliminary voting results; If the fairness assurance index is lower than the preset fairness threshold, the secondary opinion collection process will be triggered, and the preliminary voting results will be regenerated based on the opinion data obtained from the secondary collection.

[0078] In an embodiment of the present invention, the fairness assurance index is used to quantitatively evaluate the representativeness and fairness of the preliminary voting results. A low fairness assurance index means that the voting results may not fully reflect the opinions of all relevant roles, or that the opinions of certain roles are over-represented. By triggering the secondary opinion collection process, the system can collect more information and re-evaluate the decision-making plan, thereby ensuring that the final authority allocation plan is more fair and reasonable.

[0079] The calculation of the above-mentioned fairness assurance indicators can be achieved in a variety of ways. For example, the Gini coefficient can be used to measure the fairness of voting results. The Gini coefficient was originally used to measure the fairness of income distribution. In this scheme, the decision-making influence coefficient of each role can be regarded as its "income", and the voting results can be regarded as "distribution results". The Gini coefficient is calculated to evaluate the fairness of the voting results. The closer the Gini coefficient is to 0, the fairer the voting results are; the closer it is to 1, the more unfair the voting results are. Alternatively, statistical indicators such as standard deviation and variance can be used to measure the degree of dispersion of voting results. The greater the dispersion, the more dispersed the opinions of the parties are, and the lower the fairness may be.

[0080] The default fairness threshold is a pre-set value used to determine whether the current fairness assurance indicator is within an acceptable range. This threshold can be adjusted based on the actual application scenario and security requirements. For example, for high-risk permission changes, a higher fairness threshold can be set to ensure the rigor of the decision-making process; for low-risk permission changes, the fairness threshold can be appropriately lowered to improve decision-making efficiency.

[0081] The secondary opinion collection process is a process automatically initiated by the system to collect new opinions when the fairness assurance indicator of the initial voting results falls below a preset threshold. During this process, the system can resend permission expansion requests to all relevant roles, asking them to reassess and submit their opinions. To encourage more comprehensive expression of opinions, the system can provide additional supporting information, such as the opinions of other roles, historical decision records, and security risk assessment reports. In addition, the system can allow roles to modify their previous opinions or provide more detailed explanations and justifications.

[0082] After obtaining the second round of opinion collection, the system will re-perform weighted voting and generate new preliminary voting results. These new preliminary voting results will be used again to calculate the fairness assurance index. If they are still below the preset threshold, the second round of opinion collection process can be triggered again, or other measures such as manual intervention can be taken.

[0083] Through the above technical means, the present invention can effectively improve the fairness and representativeness of authority decision-making, avoid a few roles dominating the decision-making, thereby improving the overall credibility and rationality of the decision-making, and reducing potential security risks.

[0084] In some embodiments, when a decision conflict risk is identified or a fairness assurance index is determined to be lower than a preset fairness threshold, the process further includes: Parse the work intent text contained in the permission expansion request to determine the core operation and target object of the request; Based on the core operation and the target object, automatically generate at least one alternative whose scope of authority is smaller than the original request in terms of time, space, or operation type; Submit the alternative proposal for a new round of comment and weighted voting.

[0085] First, the work intent text contained in the permission expansion request is parsed to identify the core operation and target object of the request. The work intent text is a natural language description of the requester's reason and purpose for initiating a permission change request, such as "an engineer needs to remotely debug PLC parameters to resolve a sudden production line failure" or "a data analyst needs to access user behavior logs to optimize the recommendation algorithm." Parsing methods include: 1) Keyword matching: The system maintains a keyword library containing keywords for common operations such as "read," "write," "execute," and "modify," and target objects such as "PLC parameters," "user logs," and "database tables." By matching keywords in the request text, the core operation and target object are preliminarily determined. 2) Natural Language Processing (NLP)-based: Pretrained NLP models such as BERT and RoBERTa are used to perform semantic analysis on the request text, identifying entities (target objects) and relationships between entities (core operations) within the text, thereby more accurately understanding the request intent. Furthermore, knowledge graph technology can be incorporated to map keywords and entities to a predefined knowledge base to obtain richer semantic information. For example, parsing the request "An engineer needs to remotely debug PLC parameters to resolve a sudden production line failure" can extract "debugging" as the core operation and "PLC parameters" as the target object. Core operations can be further broken down into types such as "read," "write," and "monitor." Target objects can include industrial equipment, data assets, and applications.

[0086] Secondly, based on the core operation and target object, at least one alternative solution is automatically generated, with a smaller scope of permissions than the original request in terms of time, space, or operation type. Alternative solution generation strategies include: 1) Time constraints: Changing permanent permissions to temporary permissions, for example, changing "permanent access to database A" to "24-hour access to database A"; 2) Spatial constraints: Restricting the IP address or physical location of access sources, for example, changing "access to server B from anywhere" to "access to server B only within the company intranet"; 3) Operation type constraints: Restricting operation types, for example, changing "read and write PLC parameters" to "read only PLC parameters," or introducing an operation approval process to perform secondary verification for key operations; 4) Data scope constraints: Restricting the scope of data access, for example, changing "access to all user data" to "access only data for a specific user group"; and 5) Functionality degradation: Providing functionality degradation solutions, for example, changing direct PLC parameter modification to parameter modification through the simulation environment. Solution generation is not a simple random combination of constraints; rather, it is based on a predefined policy library and risk assessment model. The policy library stores security policies and alternative solution templates corresponding to different core operations and target objects. The risk assessment model is used to evaluate the security risks and availability of different alternatives and select the optimal solution. For example, for a request to "read or write PLC parameters," the system can generate alternatives such as "read only PLC parameters," "read or write PLC parameters within 2 hours," and "allow only specific IP addresses to read or write PLC parameters."

[0087] Finally, the alternative proposal is submitted for a new round of opinion gathering and weighted voting. The resulting alternative proposal is presented to the relevant actors through the user interface, and their opinions are collected. This opinion gathering and weighted voting process is consistent with the original request, ensuring fairness and transparency in the decision-making process.

[0088] The above alternative solution generation process can effectively reduce permission risks and improve decision-making efficiency. For example, in the PLC parameter debugging case mentioned above, if the security auditor objects to directly granting write permissions, the system can recommend alternative solutions such as "read-only PLC parameters" or "read and write PLC parameters within 2 hours." This can meet the engineer's debugging needs while reducing potential security risks.

[0089] like Figure 2 As shown, an embodiment of the present invention provides an access rights management system for the industrial Internet. The system aims to solve the problems of rigid decision-making, difficult collaboration and opaque processes in the existing industrial Internet rights management. Through modular design, the system realizes the automation, intelligence and transparency of rights decision-making.

[0090] The role information processing module M100 is responsible for extracting key features from user role information in the Industrial Internet system and classifying roles. In the Industrial Internet environment, roles vary, such as engineer, administrator, and operator, each with distinct responsibilities. This module uses natural language processing techniques such as the TF-IDF algorithm and K-means clustering to analyze role description data, extract text features, and then classify roles into pre-defined categories, such as "Technical Operations and Maintenance," "Production Management," and "Security Audit." The role information processing module M100 can be implemented in programming languages such as Python, utilizing natural language processing toolkits such as NLTK or spaCy for text analysis and feature extraction. Feature extraction can consider keywords and key phrases in the role description, as well as information such as the role's department and position. Clustering algorithms are not limited to K-means; for example, hierarchical clustering or DBSCAN can also be used. Through the role information processing module M100, the system can understand the scope of each role's responsibilities and areas of expertise, providing foundational data for subsequent permission decisions.

[0091] The influence assessment module M200 is responsible for calculating the influence coefficient of each role in the permission decision-making process. In permission management, the opinions of different roles have different values. For example, the opinions of security auditors have higher reference value in terms of security, while the opinions of technical operations personnel have higher reference value in terms of technical implementation. The influence assessment module M200 is based on the classification labels output by the role information processing module M100, and combined with the historical decision accuracy data of the role extracted from the historical permission decision records, it calculates the decision influence coefficient of each role through a preset weighted model. The weighted model can be adjusted according to actual conditions. For example, factors such as the role's level and experience in the organization can be added. The influence assessment module M200 makes permission decisions more scientific and reasonable by conducting quantitative evaluations of roles.

[0092] The decision integration module M300 is responsible for collecting the opinion data input by the roles regarding the current permission expansion request, and performing weighted voting on the opinion data based on the decision influence coefficient of each role to obtain preliminary voting results. In actual applications, the opinion data can be structured data such as "agree / disagree" positions and specific reasons, or it can be unstructured text data. The decision integration module M300 obtains a preliminary voting result by summarizing and analyzing the opinion data to provide a reference for subsequent decision-making. In order to improve the accuracy and efficiency of decision integration, natural language processing technology can also be used to perform sentiment analysis on the opinion data, identify positive or negative tendencies in the opinions, and incorporate the sentiment analysis results as weight factors into the weighted voting process.

[0093] The risk analysis and execution module M400 is responsible for quantifying the degree of disagreement to identify the risk of decision conflicts, and generating and executing the final authority expansion decision based on the preliminary voting results and the risk of decision conflicts. During the authority decision-making process, different roles may have different opinions, and these disagreements may bring potential risks. Based on the distribution ratio of support and opposition opinions in the preliminary voting results, the risk analysis and execution module M400 uses information entropy calculation to quantify the degree of disagreement to identify the risk of decision conflicts. If the risk of decision conflicts is high, further measures may need to be taken, such as re-evaluating the authority request or introducing experts to make decisions. The ultimate goal of the risk analysis and execution module M400 is to generate an authority expansion decision that can both meet business needs and ensure system security.

[0094] Through the collaborative work of these modules, the system automatically identifies roles and dynamically calculates decision weights based on historical data and responsibilities, replacing traditional subjective judgments. This makes the decision-making process more scientific and fair, and the resulting permission allocation scheme more reasonable, better balancing business needs and security requirements. Furthermore, by quantifying disagreement through information entropy, the system is no longer just a passive approval tool, but can proactively identify decision risks and enhance the overall intelligence of permission management.

[0095] In some embodiments, the decision integration module M300 is also used to: monitor the deviation value between each role's current opinion data and its historical decision accuracy data when performing weighted voting processing, and when the deviation value exceeds a preset threshold, dynamically lower the decision influence coefficient of the role in this processing.

[0096] By comparing the character's current opinions with their historical behavior patterns, quantifying the degree of deviation of their behavior, and dynamically adjusting their decision-making influence coefficient based on the degree of deviation, the interference of abnormal behavior on the decision-making results is reduced, thereby improving the reliability and robustness of the decision.

[0097] This embodiment significantly improves the security and reliability of the access rights management system. By dynamically monitoring and adjusting role decision weights, the system can effectively address decision-making biases caused by abnormal situations such as user account theft, malicious insider behavior, or external attacks, reducing the risk of misjudgment, preventing unreasonable granting of permissions, and ensuring the secure and stable operation of the Industrial Internet system. Even in the face of complex and changing security threats, it can maintain objectivity and accuracy in decision-making, improving overall risk prevention and control capabilities.

[0098] In some embodiments, the system also includes a decision tracing module, which structures and records the data generated during the processing of the role information processing module M100, the influence assessment module M200, the decision integration module M300, and the risk analysis and execution module M400, forming an auditable decision traceability path. This module aims to address the opaque and difficult-to-trace decision-making process in industrial internet access rights management. By structured recording of key data in the access rights management process, it creates an auditable decision traceability path, thereby enhancing the transparency and reliability of the system and facilitating post-analysis and accountability. The module collects data generated by the role information processing module M100, the influence assessment module M200, the decision integration module M300, and the risk analysis and execution module M400 at each processing stage and stores this data in a structured format, such as log files, databases, or specialized audit systems. Structured recording means that data is stored in a predefined format, such as JSON, XML, or a relational database table, to facilitate querying, analysis, and report generation. This structured data clearly reflects the participants, basis, risk assessment, and final outcome of each decision link, forming a complete decision chain. By tracing back permissions decisions, managers can quickly identify potential risks resulting from improper permission allocation, such as abuse of permissions and unauthorized access. When a security incident occurs, the detailed data provided by the traceability module helps quickly locate the root cause, assess the scope of impact, and implement appropriate remedial measures. Furthermore, comprehensive decision traceability records provide strong support for compliance audits, demonstrating that the permission management process complies with relevant laws, regulations, and security standards.

[0099] By implementing the Decision Tracking module, the entire rights management decision-making process can be monitored and audited, significantly improving the transparency and credibility of the system. In the event of a security incident or compliance issue, managers can quickly identify the root cause and take timely countermeasures to minimize losses.

[0100] In some embodiments, the system also includes an alternative solution generation engine, which is used to analyze the work intention of the authority expansion request when the risk analysis and execution module M400 identifies the decision conflict risk, and automatically generate at least one alternative solution with a smaller authority scope than the original request for the decision integration module M300 to perform a new round of decision processing.

[0101] The alternative solution generation engine is used to analyze the work intention of the permission expansion request when the risk analysis and execution module M400 identifies the risk of decision conflict, and automatically generate at least one alternative solution with a smaller scope of authority than the original request, so that the decision integration module M300 can perform a new round of decision processing. This embodiment provides a risk mitigation mechanism. When the system detects that there is a high risk in the permission expansion decision, such as large differences of opinion and strong opposition from security auditors, the alternative solution generation engine intervenes and no longer simply rejects the request. Instead, it attempts to provide an alternative solution with lower risk and smaller scope of authority while meeting the basic work needs of the requester.

[0102] The alternative solution generation engine parses the work intent text contained in the permission expansion request to understand the requester's true purpose. For example, if the permission expansion request is "Operations Engineer requests full access to the production database," the engine will analyze the work intent, which could be "troubleshooting system issues," "data analysis," "routine maintenance," etc. Intent parsing can use a variety of natural language processing technologies, such as: Rule-based parsing: Build a series of rules to associate common verbs and nouns with predefined work intents. For example, "view" or "read" might correspond to "data analysis" or "troubleshooting," and "modify" or "write" might correspond to "configuration change" or "system maintenance."

[0103] Machine learning-based parsing: Use pre-trained language models such as BERT and RoBERTa to encode the request text, and then train a classifier to map the encoded text to predefined work intent categories.

[0104] Hybrid approach: Combining rules and machine learning, first using rules for preliminary analysis, and then using machine learning models for secondary confirmation or refinement.

[0105] Based on the parsed work intent, the engine will query a permissions knowledge base or security policy library to find alternative solutions that meet the intent and have a lower risk level. The knowledge base can take various forms: Rules Engine: Define a set of rules that describe possible alternatives for different work intentions. For example, if the intention is to "troubleshoot system failures," the rules can suggest "granting read-only permissions" or "providing a restricted debugging interface."

[0106] Graph databases: These databases construct a graph structure containing information such as resources, permissions, roles, and risks. Graph query algorithms are then used to identify alternative solutions. For example, a query can be performed to determine which permissions satisfy the intent of 'troubleshooting system failures' and have a lower risk level than 'full access'.

[0107] The reduction in the scope of authority of the alternative can be reflected in several dimensions: Time dimension: Change permanent permissions to temporary permissions. For example, grant permissions only during troubleshooting and revoke them immediately after the troubleshooting is resolved.

[0108] Spatial dimension: Limit access source IP addresses or network zones. For example, only allow access from the company intranet or a specific VPN connection.

[0109] Operation type dimension: downgrade read and write permissions to read-only permissions, or provide restricted API interfaces that only allow specific operations.

[0110] Resource dimension: Limits the scope of accessible resources. For example, only allowing access to specific database tables or specific file directories.

[0111] The generated alternatives are submitted to the decision-making integration module M300 for a new round of opinion collection and weighted voting. This makes the decision-making process more flexible and adaptable, meeting business needs while minimizing security risks. By intelligently recommending lower-risk alternatives, the system enhances the intelligence of permission management, avoids the impact of blanket rejection of permission requests on business operations, and reduces security risks.

[0112] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A method for managing access rights of the industrial Internet, characterized in that: include: Obtaining a dataset of responsibilities descriptions of roles related to the permission expansion request, and performing feature extraction and cluster analysis on the responsibilities description data to obtain a classification label for each role; Based on the classification label of each role and combined with the historical decision accuracy data of the role extracted from the historical authority decision records, the decision influence coefficient of each role is calculated through a preset weighted model; Obtaining the opinion data input by the role regarding the current permission expansion request, and performing weighted voting on the opinion data based on the decision-making influence coefficient of each role to obtain a preliminary voting result; Based on the distribution ratio of support and opposition in the preliminary voting results, the degree of disagreement is quantified using information entropy calculation to identify the risk of decision conflict; A final authority expansion decision is generated and executed based on the preliminary voting results and the decision conflict risk.

2. The method according to claim 1, characterized in that The step of performing feature extraction and cluster analysis on the job description data includes: Using a word frequency-inverse document frequency algorithm, the job description data is converted into a text feature vector; The text feature vectors are clustered using a K-means algorithm, thereby assigning the classification label to each role.

3. The method according to claim 1, characterized in that The preset weighted model also combines the decision participation frequency data of each role obtained from the historical authority decision records, and performs weighted calculations together with the historical decision accuracy data and the responsibility weights corresponding to the classification labels.

4. The method according to claim 1, wherein The step of performing weighted voting processing further includes: Before weighting, monitor the deviation between each role's current opinion data and its historical decision accuracy data; When the deviation value exceeds a preset threshold, the decision-making influence coefficient of the role in this weighted voting process is dynamically lowered.

5. The method according to claim 1, wherein After obtaining the opinion data, the method further includes: Using a natural language processing model to perform sentiment analysis on the opinion data, and determining a sentiment weight value for each opinion data; The step of performing weighted voting processing specifically includes multiplying the decision-making influence coefficient of each role by the emotional weight value corresponding to the opinion data submitted by the role to obtain an effective decision-making influence; and using the effective decision-making influence to weight the opinion data.

6. The method according to claim 1, characterized in that After the final permission expansion decision is made, the following also needs to be done: All data and processing processes of the classification labels, decision influence coefficients, opinion data, preliminary voting results, and decision conflict risks are structured and recorded in a visual log module to form a traceable decision audit path.

7. The method according to claim 1, characterized in that Before making the final decision on privilege expansion, the following also needs to be done: Calculating the fairness assurance index corresponding to the preliminary voting results; If the fairness guarantee index is lower than the preset fairness threshold, the secondary opinion collection process is triggered, and the preliminary voting result is regenerated based on the opinion data obtained from the secondary collection.

8. The method according to claim 7, characterized in that When the decision conflict risk is identified or the fairness assurance index is determined to be lower than a preset fairness threshold, the method further includes: Parsing the work intent text contained in the permission expansion request to determine the core operation and target object of the request; Based on the core operation and the target object, automatically generate at least one alternative solution whose scope of authority is smaller than the original request in terms of time, space, or operation type; The alternatives are submitted for a new round of opinion-taking and weighted voting.

9. An access rights management system for the industrial Internet, characterized in that: include: A role information processing module is used to obtain a role description dataset related to the permission expansion request, and perform feature extraction and cluster analysis on the role description data to determine a classification label for each role; An influence assessment module is configured to determine the decision influence coefficient of each role by calculating the influence coefficient using a preset weighting model based on the classification label of each role and the historical decision accuracy data of the role extracted from the historical authority decision records; A decision integration module is used to obtain the opinion data input by the roles regarding the current permission expansion request, and perform weighted voting on the opinion data based on the decision influence coefficient of each role to obtain a preliminary voting result; The risk analysis and execution module is used to quantify the degree of disagreement based on the distribution ratio of support and opposition opinions in the preliminary voting results by using information entropy calculation to identify decision conflict risks, and generate and execute the final authority expansion decision based on the preliminary voting results and the decision conflict risks.

10. The system according to claim 9, characterized in that The decision integration module is also used to: monitor the deviation value between each role's current opinion data and its historical decision accuracy data when performing weighted voting processing, and dynamically lower the role's decision influence coefficient in this processing when the deviation value exceeds a preset threshold.

Citation Information

Patent Citations

  • Model optimization method and system of treatment scheme recommendation system

    CN109243561A

  • Decentralized autonomous organization adaptive probability weighted voting method

    CN114971548A

  • Distributed fault detection and dynamic task scheduling system for unmanned ship cluster

    CN119512107A

  • Key information extraction and mass attitude evaluation method based on large language model

    CN119513295A

  • Zero-trust API dynamic access control method, computer device and medium

    CN120296755A

Cited By

  • Dynamic authority management system and method and multi-source heterogeneous message middleware

    CN121000532A

  • A dynamic permission management system, method, and multi-source heterogeneous message middleware

    CN121000532B